MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 90bab0433b3121b587082f8dd1ac5ccac5c115566a8f780071d3926ab3d505ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 90bab0433b3121b587082f8dd1ac5ccac5c115566a8f780071d3926ab3d505ba
SHA3-384 hash: a585cbfc62c3f6a0f36e46e8612c407636c11e7720e55b70c140743db430e19eb19d97b32694b30392f7354acdab2100
SHA1 hash: 0091156acac0e2061caf853644223152f164fe55
MD5 hash: 4bd60c62d8f5d0919c510e31a21e96bc
humanhash: five-single-ten-march
File name:c.sh
Download: download sample
Signature Mirai
File size:834 bytes
First seen:2025-09-11 05:29:34 UTC
Last seen:2025-09-11 07:43:21 UTC
File type: sh
MIME type:text/plain
ssdeep 12:3J373ZeL1S73ZeCYK73ZerNIl5173Ze40LKF73ZeK+OFp73Ze3jMx73ZeZT073Zg:3J3o8Y9NI7UK9+ICj1TClWtgMnn
TLSH T16301DEDC77F1629FEA08DE28E176809C9130B4C0326C0E66E9E50CF6D8D93097E65E79
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://161.97.106.129/systemcl/arma2812bf91c1836b0749615f8c92f49b055ed1152a0cfcb03cffb4473388ae1f9 Miraielf mirai
http://161.97.106.129/systemcl/arm5467ca3ecdb388a31f9687f3f93134ae992fbfbe2936cfbd700c3d198b3b65ecb Miraielf mirai
http://161.97.106.129/systemcl/arm67a4627901da5e02ceacaf688cc103b4944a3cf75b4f1f4316ee638893eaa4104 Miraielf mirai
http://161.97.106.129/systemcl/arm71745a1dc09e108e719186017f4d6f10e1835aa4ba3f74b50b8394e3268c66524 Miraielf mirai
http://161.97.106.129/systemcl/m68k19abfca0200531ee5ddc2dd7bc4454af84d9ffe0ef2e12cd2a54fc828ebdc659 Miraielf mirai
http://161.97.106.129/systemcl/mipsad42066092b60784e1579fb3742cf3a41450dacc13b254e9c3a0c5b84aaf0db4 Miraielf mirai
http://161.97.106.129/systemcl/mpsl7365564e3fc5bc60caa91eb8b6b87a6d8da423389be87134899fcd0caaeb3242 Miraielf mirai
http://161.97.106.129/systemcl/ppcabfd19ac36a02a8d3552a65a6e023b7499af427f7ea558cbc5064b8475bd955e Miraielf mirai
http://161.97.106.129/systemcl/sh4b5d5a320320766751e9a1e31bc6ff850196e0c3f0b5baee15eee600b8a3cdae2 Miraielf mirai
http://161.97.106.129/systemcl/spc2b4e44a8a37c63ce0a2c007bb22d903ae9d13b643b6b556f4d15199926cdd54c Miraielf mirai
http://161.97.106.129/systemcl/x862e9b4bb064c078485eab38389da45cfecd1f865d77cd5c199ae3c2fe195daf72 Miraielf mirai
http://161.97.106.129/systemcl/x86_6447a0fa2b9aa3ebdb48324d5ad43903187a528176193716db81991191b3d3b230 Miraielf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-09-10T09:41:00Z UTC
Last seen:
2025-09-10T09:41:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=bc045e3f-1a00-0000-93c4-6c30dd090000 pid=2525 /usr/bin/sudo guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534 /tmp/sample.bin guuid=bc045e3f-1a00-0000-93c4-6c30dd090000 pid=2525->guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534 execve guuid=6ae50142-1a00-0000-93c4-6c30e7090000 pid=2535 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=6ae50142-1a00-0000-93c4-6c30e7090000 pid=2535 execve guuid=d432d24a-1a00-0000-93c4-6c30fa090000 pid=2554 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=d432d24a-1a00-0000-93c4-6c30fa090000 pid=2554 execve guuid=1f24144b-1a00-0000-93c4-6c30fc090000 pid=2556 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=1f24144b-1a00-0000-93c4-6c30fc090000 pid=2556 clone guuid=816a204b-1a00-0000-93c4-6c30fd090000 pid=2557 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=816a204b-1a00-0000-93c4-6c30fd090000 pid=2557 execve guuid=44e62c54-1a00-0000-93c4-6c30140a0000 pid=2580 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=44e62c54-1a00-0000-93c4-6c30140a0000 pid=2580 execve guuid=184a9854-1a00-0000-93c4-6c30160a0000 pid=2582 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=184a9854-1a00-0000-93c4-6c30160a0000 pid=2582 clone guuid=40c0a754-1a00-0000-93c4-6c30170a0000 pid=2583 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=40c0a754-1a00-0000-93c4-6c30170a0000 pid=2583 execve guuid=2eeca959-1a00-0000-93c4-6c30280a0000 pid=2600 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=2eeca959-1a00-0000-93c4-6c30280a0000 pid=2600 execve guuid=1412005a-1a00-0000-93c4-6c302b0a0000 pid=2603 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=1412005a-1a00-0000-93c4-6c302b0a0000 pid=2603 clone guuid=7475065a-1a00-0000-93c4-6c302c0a0000 pid=2604 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=7475065a-1a00-0000-93c4-6c302c0a0000 pid=2604 execve guuid=e5a5e35d-1a00-0000-93c4-6c30370a0000 pid=2615 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=e5a5e35d-1a00-0000-93c4-6c30370a0000 pid=2615 execve guuid=a3bd245e-1a00-0000-93c4-6c30380a0000 pid=2616 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=a3bd245e-1a00-0000-93c4-6c30380a0000 pid=2616 clone guuid=35ea2c5e-1a00-0000-93c4-6c30390a0000 pid=2617 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=35ea2c5e-1a00-0000-93c4-6c30390a0000 pid=2617 execve guuid=1fd90262-1a00-0000-93c4-6c30460a0000 pid=2630 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=1fd90262-1a00-0000-93c4-6c30460a0000 pid=2630 execve guuid=35856f62-1a00-0000-93c4-6c30470a0000 pid=2631 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=35856f62-1a00-0000-93c4-6c30470a0000 pid=2631 clone guuid=68947d62-1a00-0000-93c4-6c30480a0000 pid=2632 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=68947d62-1a00-0000-93c4-6c30480a0000 pid=2632 execve guuid=8bf10b6d-1a00-0000-93c4-6c30680a0000 pid=2664 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=8bf10b6d-1a00-0000-93c4-6c30680a0000 pid=2664 execve guuid=6c89586d-1a00-0000-93c4-6c306a0a0000 pid=2666 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=6c89586d-1a00-0000-93c4-6c306a0a0000 pid=2666 clone guuid=35c1676d-1a00-0000-93c4-6c306b0a0000 pid=2667 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=35c1676d-1a00-0000-93c4-6c306b0a0000 pid=2667 execve guuid=99750971-1a00-0000-93c4-6c30760a0000 pid=2678 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=99750971-1a00-0000-93c4-6c30760a0000 pid=2678 execve guuid=ce006571-1a00-0000-93c4-6c30790a0000 pid=2681 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=ce006571-1a00-0000-93c4-6c30790a0000 pid=2681 clone guuid=1f607771-1a00-0000-93c4-6c307a0a0000 pid=2682 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=1f607771-1a00-0000-93c4-6c307a0a0000 pid=2682 execve guuid=ac15c075-1a00-0000-93c4-6c30870a0000 pid=2695 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=ac15c075-1a00-0000-93c4-6c30870a0000 pid=2695 execve guuid=e06ffd75-1a00-0000-93c4-6c30890a0000 pid=2697 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=e06ffd75-1a00-0000-93c4-6c30890a0000 pid=2697 clone guuid=a6f90a76-1a00-0000-93c4-6c308a0a0000 pid=2698 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=a6f90a76-1a00-0000-93c4-6c308a0a0000 pid=2698 execve guuid=3e77987e-1a00-0000-93c4-6c30a10a0000 pid=2721 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=3e77987e-1a00-0000-93c4-6c30a10a0000 pid=2721 execve guuid=0f02ce7e-1a00-0000-93c4-6c30a30a0000 pid=2723 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=0f02ce7e-1a00-0000-93c4-6c30a30a0000 pid=2723 clone guuid=ff62d57e-1a00-0000-93c4-6c30a40a0000 pid=2724 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=ff62d57e-1a00-0000-93c4-6c30a40a0000 pid=2724 execve guuid=6224dd83-1a00-0000-93c4-6c30b10a0000 pid=2737 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=6224dd83-1a00-0000-93c4-6c30b10a0000 pid=2737 execve guuid=0f305284-1a00-0000-93c4-6c30b30a0000 pid=2739 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=0f305284-1a00-0000-93c4-6c30b30a0000 pid=2739 clone guuid=c6656184-1a00-0000-93c4-6c30b40a0000 pid=2740 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=c6656184-1a00-0000-93c4-6c30b40a0000 pid=2740 execve guuid=f570448d-1a00-0000-93c4-6c30ce0a0000 pid=2766 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=f570448d-1a00-0000-93c4-6c30ce0a0000 pid=2766 execve guuid=c4df988d-1a00-0000-93c4-6c30d00a0000 pid=2768 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=c4df988d-1a00-0000-93c4-6c30d00a0000 pid=2768 clone guuid=4d35a48d-1a00-0000-93c4-6c30d10a0000 pid=2769 /usr/bin/curl net send-data guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=4d35a48d-1a00-0000-93c4-6c30d10a0000 pid=2769 execve guuid=4834e797-1a00-0000-93c4-6c30e80a0000 pid=2792 /usr/bin/chmod guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=4834e797-1a00-0000-93c4-6c30e80a0000 pid=2792 execve guuid=ed702c98-1a00-0000-93c4-6c30ea0a0000 pid=2794 /usr/bin/dash guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=ed702c98-1a00-0000-93c4-6c30ea0a0000 pid=2794 clone guuid=5fbe3c98-1a00-0000-93c4-6c30eb0a0000 pid=2795 /usr/bin/rm delete-file guuid=493ea741-1a00-0000-93c4-6c30e6090000 pid=2534->guuid=5fbe3c98-1a00-0000-93c4-6c30eb0a0000 pid=2795 execve 2b1801dc-b67a-5da1-8e84-0d7a99e1894a 161.97.106.129:80 guuid=6ae50142-1a00-0000-93c4-6c30e7090000 pid=2535->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 90B guuid=816a204b-1a00-0000-93c4-6c30fd090000 pid=2557->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 91B guuid=40c0a754-1a00-0000-93c4-6c30170a0000 pid=2583->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 91B guuid=7475065a-1a00-0000-93c4-6c302c0a0000 pid=2604->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 91B guuid=35ea2c5e-1a00-0000-93c4-6c30390a0000 pid=2617->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 91B guuid=68947d62-1a00-0000-93c4-6c30480a0000 pid=2632->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 91B guuid=35c1676d-1a00-0000-93c4-6c306b0a0000 pid=2667->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 91B guuid=1f607771-1a00-0000-93c4-6c307a0a0000 pid=2682->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 90B guuid=a6f90a76-1a00-0000-93c4-6c308a0a0000 pid=2698->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 90B guuid=ff62d57e-1a00-0000-93c4-6c30a40a0000 pid=2724->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 90B guuid=c6656184-1a00-0000-93c4-6c30b40a0000 pid=2740->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 90B guuid=4d35a48d-1a00-0000-93c4-6c30d10a0000 pid=2769->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 93B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-09-10 17:56:26 UTC
File Type:
Text (Shell)
AV detection:
15 of 37 (40.54%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 90bab0433b3121b587082f8dd1ac5ccac5c115566a8f780071d3926ab3d505ba

(this sample)

  
Delivery method
Distributed via web download

Comments